From f3b4c2269a101d4da21e42b2bb569b3ba06d5a02 Mon Sep 17 00:00:00 2001 From: NK Date: Wed, 25 Mar 2026 00:54:33 +0100 Subject: [PATCH] Fix Python availability claim: included in ESXi 6.x+, not all versions --- docs/esxi.md | 2 +- tools/vmkatz_loader.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/esxi.md b/docs/esxi.md index 6695419..55615c0 100644 --- a/docs/esxi.md +++ b/docs/esxi.md @@ -23,7 +23,7 @@ esxcli system settings advanced set -o /User/execInstalledOnly -i 0 When `execInstalledOnly` is set to 1 (default on ESXi 7.0+), unsigned binaries cannot be executed directly. The included Python loader (`tools/vmkatz_loader.py`, bundled in the ESXi release archive) bypasses this by loading vmkatz into anonymous memory pages — ESXi allows `PROT_EXEC` on anonymous mappings while blocking `execve` on unsigned files. -Python is VIB-signed on all ESXi versions and can execute normally. +Python is included in ESXi 6.x and later (used internally by VMware hostd/CIM providers) and can execute normally regardless of VIB settings. ```bash # Upload both files diff --git a/tools/vmkatz_loader.py b/tools/vmkatz_loader.py index 5a63989..b67d111 100644 --- a/tools/vmkatz_loader.py +++ b/tools/vmkatz_loader.py @@ -6,7 +6,7 @@ Bypasses execInstalledOnly (VIB protection) by loading the vmkatz static binary into anonymous mmap pages with PROT_EXEC. ESXi VMkernel allows PROT_EXEC on anonymous mappings but blocks execve on unsigned binaries. -Python is VIB-signed on ESXi, so it can execute normally. +Python is included in ESXi 6.x+ and executes regardless of VIB settings. We parse the ELF, map segments, apply relocations, build a proper initial stack (argc/argv/envp/auxv), and jump to _start.